<oembed><type>rich</type><version>1.0</version><author_name>npub1g5zswf6y48f7fy90jf3tlcuwdmjn8znhzaa4vkmtxaeskca8hpss23ms3l</author_name><author_url>https://nostr.ae/npub1g5zswf6y48f7fy90jf3tlcuwdmjn8znhzaa4vkmtxaeskca8hpss23ms3l</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2020-03-10&#xA;📝 Original message:&#xA;Good morning Rusty, et al.,&#xA;&#xA;&#xA;&gt; Note that this means no payment secret is necessary, since the incoming&#xA;&gt; `blinding` serves the same purpose. If we wanted to, we could (ab)use&#xA;&gt; payment_secret as the first 32-bytes to put in Carol&#39;s enc1 (i.e. it&#39;s&#xA;&gt; the ECDH for Carol to decrypt enc1).&#xA;&#xA;I confess to not reading everything in detail, but it seems to me that, with payment point + scalar and path decorrelation, we need to establish a secret with each hop anyway (the blinding scalar for path decorrelation), so if you need a secret per hop, possibly this could be reused as well?&#xA;&#xA;Regards,&#xA;ZmnSCPxj</html></oembed>